Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.
Rules on DetectionCode tagged with T1001 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Suspicious LDAP-Attributes Used | high | windows / NULL | T1001.003 |
| ADSI-Cache File Creation By Uncommon Tool | medium | windows / file_event | T1001.003 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Windows PowGoop Beacon Decoding | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1001 |
| Windows Suspicious QEMU Execution | TTP | NULL | Sysmon EventID 1 | T1001 |
| Used by | Procedure example |
|---|---|
| GroupGamaredon Group | Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings. |
| Used by | Procedure example |
|---|---|
| MalwareDarkGate | DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining. |
| Toolevilginx2 | evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions. |
| MalwareFlawedAmmyy | FlawedAmmyy may obfuscate portions of the initial C2 handshake. |
| MalwareFRAMESTING | FRAMESTING can send and receive zlib compressed data within `POST` requests. |
| MalwareFunnyDream | FunnyDream can send compressed and obfuscated packets to C2. |
| MalwareNinja | Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests. |
| MalwareOkrum | Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests. |
| MalwareRDAT | RDAT has used encoded data within subdomains as AES ciphertext to communicate from the host to the C2. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Wocao | During Operation Wocao, threat actors encrypted IP addresses used for "Agent" proxy hops with RC4. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.